Privacy Policy
This document explains exactly what personal information PrintForge Digital collects, how we use it, who we share it with, and how long we keep it. Written in plain English, not in legalese, because a policy you cannot read is not really a policy.
The short version
Contact details, order information, and your design files. Nothing more, nothing sold.
Not to advertisers, not to data brokers, not to anyone. Full stop.
Stored on encrypted servers at our shop, not in the cloud. Deleted 90 days after your last order by default.
Email [email protected] and we will remove your data within 30 days.
Introduction
PrintForge Digital LLC ("PrintForge", "we", "us", or "our") operates the website at printforge.digital and provides custom 3D printing services from our shop at 2150 Market Street, Suite 340, San Francisco, CA 94114.
This Privacy Policy describes how we collect, use, share, and protect personal information when you:
- Visit our website
- Upload a design file for a quote
- Place an order for 3D printed parts
- Communicate with us by email, phone, or through our forms
- Apply for a job at our shop
- Visit our physical location
By using our services, you agree to the practices described in this policy. If you do not agree, please do not use the site or submit files.
Information we collect
We collect information in three ways: directly from you, automatically through your browser, and from third-party services you interact with during an order.
Information you give us directly
| Category | Examples | Required? |
|---|---|---|
| Contact details | Name, email address, phone number, company name, job title | Required to place an order |
| Order details | Shipping address, billing address, purchase order number, tax ID | Required to complete a sale |
| Design files | STL, STEP, STP, and OBJ files, along with any notes or drawings you include | Required for custom printing |
| Payment information | Card type and last four digits, billing ZIP code. Full card numbers never reach our servers. | Required for payment |
| Communication | Emails, form submissions, phone notes, meeting summaries | Optional but helpful |
| Employment information | Résumé, work history, references, if you apply for a role | Required to apply |
Information collected automatically
When you visit our website, our servers log standard technical information that every web server collects:
- IP address and approximate geographic region (city-level only)
- Browser type, operating system, and device type
- Pages visited, time on page, and referring URL
- Date and time of each request
We use this data only in aggregate to keep the site running and to understand which pages are useful. We do not build individual visitor profiles.
Information from third parties
- Payment processors — Stripe and Square confirm that a payment succeeded and return a transaction ID. They do not share card numbers with us.
- Shipping carriers — UPS, FedEx, and USPS return tracking numbers and delivery status.
- Analytics — We use a privacy-focused analytics tool that does not set cookies and does not collect personal identifiers.
How we use information
Every piece of data we collect is used for one of the following purposes:
- Fulfilling your order — Printing, inspecting, packing, and shipping the parts you ordered.
- Quoting and communication — Responding to your questions, sending quotes, and updating you on order status.
- Billing and accounting — Processing payments, issuing invoices, and complying with tax law.
- Customer support — Investigating complaints, processing reprints, and answering follow-up questions.
- Site security — Detecting abuse, blocking scrapers, and preventing fraudulent orders.
- Legal compliance — Responding to lawful requests, retaining records where required by law.
- Hiring — Reviewing job applications and contacting candidates.
We do not use your information for advertising, we do not sell it, and we do not share it for cross-context behavioral advertising.
Your design files
Design files deserve their own section because they are often the most sensitive thing a customer sends us. Here is exactly what happens to them.
Where files are stored
Uploaded design files are stored on encrypted local servers located inside our San Francisco shop. Files are not uploaded to any cloud storage service, are not backed up to third-party infrastructure, and are not accessible from outside our local network.
Who can access them
Access is limited to the three roles that need it to complete your order:
- The application engineer who reviews printability
- The slicing engineer who prepares the print job
- The technician who runs the print
Shipping, accounting, and sales staff do not have access to customer design files.
How long we keep them
By default, design files are deleted 90 days after your most recent order ships. If you would like files retained longer for repeat production, you can request an extended retention period in writing and we will hold them for the duration you specify.
NDAs and confidentiality
We sign mutual NDAs on any order involving proprietary customer IP. We can sign your template or provide ours. Files must not be uploaded until the NDA is signed by both parties.
What we will never do
- Share your files with any third party without written instruction
- Publish your geometry, part numbers, or customer name without written permission
- Use your designs to train any AI or machine learning model
- Sell or license your files under any circumstance
Cookies and tracking
We keep our cookie usage minimal. Here is the full list:
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| cookieConsent | Functional | Remembers whether you accepted or declined the cookie banner | 12 months |
| Session identifiers | Functional | Maintains your form progress during a single visit | Session only |
We do not use advertising cookies, tracking pixels, or cross-site identifiers. We do not embed Facebook, TikTok, or Google tracking code. We do not run retargeting campaigns.
You can disable cookies in your browser settings at any time. Doing so will not prevent you from using the site, though the cookie banner will reappear on each visit. Full details are available in our Cookie Policy.
Data retention
We keep different types of data for different periods, based on what we need and what the law requires.
| Data type | Retention period | Why |
|---|---|---|
| Design files | 90 days after last order | Enables reprints without re-upload |
| Order records | 7 years | Tax and accounting law |
| Contact information | Until you request deletion | Customer support and repeat orders |
| Email correspondence | 5 years | Dispute resolution and record keeping |
| Job applications | 12 months | Consideration for future roles |
| Website logs | 90 days | Security and abuse detection |
When retention periods end, data is securely deleted from active systems. Backups age out on the same schedule.
Security measures
We take the security of your data seriously. Measures we have in place include:
- Full-disk encryption on all servers and workstations
- Encrypted local storage for customer files, isolated from the public internet
- Two-factor authentication on all business accounts
- Password managers, no shared credentials
- Physical security on the file server room, badge access only
- Regular software updates and prompt security patching
- Annual third-party security review
No system is perfectly secure. If we ever experience a data breach that affects your personal information, we will notify you and the relevant authorities within 72 hours of discovering the breach, in accordance with applicable law.
To report a security concern, email [email protected]. We respond to every report within one business day.
Your privacy rights
Regardless of where you live, we extend the following rights to every customer:
Right to know
You can ask what personal information we hold about you and receive a copy within 30 days.
Right to correct
You can request corrections to any inaccurate data we hold.
Right to delete
You can ask us to delete your personal data, subject to legal retention requirements.
Right to opt out
You can opt out of any marketing communication with one click.
Right to portability
You can request your data in a structured, machine-readable format.
Right to complain
You can file a complaint with us directly or with your local data protection authority.
To exercise any of these rights, email [email protected] with the subject line "Privacy Rights Request." We verify identity with a code sent to your email on file, then respond within 30 days. There is no fee for any of these requests.
California residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Categories of personal information we collect
In the last 12 months, we have collected the following categories of personal information: identifiers (name, email, phone, IP address), commercial information (order history), internet activity (site usage logs), and professional information (for job applicants).
We do not sell or share your information
We do not sell your personal information for money or any other valuable consideration, and we do not share it for cross-context behavioral advertising. This has been true since we opened in 2019 and it will remain true.
Additional rights for California residents
- Right to know specific pieces of personal information we hold
- Right to know categories of sources from which we collected information
- Right to know categories of third parties with whom we share information
- Right to limit use of sensitive personal information (we do not collect sensitive personal information)
- Right to non-discrimination for exercising your privacy rights
To exercise any CCPA or CPRA right, contact us at [email protected] or call (628) 214-7390. An authorized agent may submit a request on your behalf with written permission.
International users
Our servers and operations are located in the United States. If you are accessing our site from outside the US, please be aware that any information you provide will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
For customers in the European Economic Area, United Kingdom, or Switzerland, we process your data under the following legal bases:
- Contract performance — to fulfill your order
- Legitimate interest — to run and secure our business
- Legal obligation — to retain records as required by tax law
- Consent — for any optional communications you opt into
International shipping is quoted case by case, and customers outside the US are responsible for complying with their own local import and data protection regulations.
Children's privacy
Our services are designed for professional and hobbyist use by adults. We do not knowingly collect personal information from children under the age of 13. If we become aware that we have collected information from a child under 13 without verified parental consent, we will delete that information promptly.
If you believe a child has provided information to us, contact [email protected] and we will investigate and remove the data within two business days.
Changes to this policy
We update this policy when our practices change or when the law requires it. Every version is dated and logged below.
When we make material changes, we will send an email to customers with active accounts and post a banner on the site for at least 30 days before the changes take effect.
How to contact us
For any question about this policy, any privacy rights request, or any concern about how we handle your data, contact us by any of the following methods.
2150 Market Street, Suite 340
San Francisco, CA 94114
Questions About Your Data?
Email our privacy team directly. We respond to every request within one business day.